ALMC
ALMC Security Logo - Mantenimiento Web, Programación Web Barcelona, Servidores Barcelona, Ciberseguridad Barcelona
  • English
    Español English Français Català

Quick search

Results without leaving the page.

Type to search ALMC products, services, articles and tools.

View all results
Habla a nuestro AgenteIA · respuestas al instante · 24/7
  • HomeALMC
  • ALMCAbout Us
  • ALMC SECURITY S.L.U.Contact
  • Posts
    • Posts
    • Categorías
    • Etiquetas
    • Estados
  • Soluciones
    • Desarrollo Web en Lleida — Diseño a Medida que Vende
    • Tienda Online a Medida — E-commerce que Vende de Verdad
    • Chatbot IA para Empresas — Automatiza tu Atención al Cliente
    • Automatización de Procesos para Empresas — Menos Tareas, Más Resultados
    • Desarrollo de Apps Móviles — iOS y Android a Medida
  • Services
    • Cybersecurity
      • Security Audits and Pentesting
      • Monitoring & Incident Response (SIEM)
      • System & Server Hardening
      • Compliance Consulting (GDPR, ENS, ISO 27001)
      • Cloud Security (AWS, Azure, Google Cloud)
    • Programming
      • Full Stack Web Development Laravel, Vue.js
      • Process Automation (Scripts and Bots)
      • Process Automation Scripts and Bots
      • API Integrations & Microservices
      • Code Maintenance and Optimization
    • Servers
      • Server Management & Monitoring
      • Cloud Migration (AWS, Azure, Google Cloud)
      • Performance Optimization
      • Virtualization & Containers (Docker, Kubernetes)
      • Backup & Disaster Recovery Plans
    • Malware Removal
    • Website Maintenance
      • WordPress Maintenance
      • PrestaShop Maintenance
      • Magento Maintenance
      • Joomla Maintenance
      • Drupal Maintenance
      • Shopify Maintenance
      • Wix Maintenance
      • Concrete5 Maintenance
      • HTML Maintenance
      • PHP Maintenance
      • JavaScript Maintenance
      • Python Maintenance
    • Website Repair
      • Hacked site cleanup
      • Fix WordPress
      • Fix PrestaShop
      • Fix Magento
      • Fix Joomla
      • Fix Drupal
      • Fix Shopify
      • Fix OpenCart
      • Fix Moodle
  • Industries
    • 3D Printing & Additive
    • Accounting
    • Advertising & Marketing
    • Aerospace & Defense
    • Agriculture
    • Architecture & Engineering
    • Arts & Culture
    • Automotive
    • Banking & Finance
    • Biomedical Research
    • Biotechnology
    • Breweries
    • Call Centers & BPO
    • Chemicals
    • Cleaning Services
    • Clinics
    • Cloud Providers
    • Construction
    • Consulting
    • Cosmetics & Beauty
    • Courier & Last Mile
    • Cybersecurity
    • Data Centers
    • Defense & Security
    • E-Commerce
    • EdTech
    • Education (K-12)
    • Electrical Equipment
    • Electronics
    • Environmental NGOs
    • Environmental Services
    • Events & Conferences
    • Facilities Management
    • Fashion & Luxury
    • FinTech
    • Fishing & Aquaculture
    • Food & Beverage Manufacturing
    • Forestry
    • Freight Transport
    • Furniture
    • Gaming
    • Government & Public Administration
    • GovTech
    • Gyms & Fitness Centers
    • Healthcare Providers
    • HealthTech
    • Higher Education
    • Home Appliances
    • Home Services
    • Hospitality
    • Hospitals
    • Human Resources
    • Insurance
    • InsurTech
    • Internet & Web Services
    • Investment & Asset Management
    • IT Services
    • Jewelry
    • Landscaping & Gardening
    • Legal Services
    • Logistics & Supply Chain
    • Machinery
    • Maritime
    • Media & Entertainment
    • Medical Devices
    • Metals
    • Mining
    • Music Industry
    • Nonprofit & NGOs
    • Oil & Gas
    • Paper & Print Media
    • Paper & Pulp
    • Pharmaceuticals
    • Photography & Video
    • Plastics
    • Postal & Courier
    • Printing
    • Private Education & Academies
    • Property Development
    • Property Management
    • PropTech
    • Public Safety & Emergency
    • Publishing
    • Rail & Public Transport
    • Real Estate
    • Real Estate Agencies
    • Religious Organizations
    • Renewable Energy
    • Research & Development
    • Research Labs
    • Restaurants & Food Service
    • Retail
    • Security Services
    • Semiconductors
    • Software Development
    • Sports & Fitness
    • Sports Clubs
    • Staffing & Recruitment
    • Telecommunications
    • Textile & Apparel
    • Tobacco
    • Toys
    • Travel & Tourism
    • Travel Agencies
    • Utilities
    • Veterinary & Animal Care
    • Warehousing
    • Waste Management
    • Water Treatment
    • Wholesale
    • Wineries & Vineyards
  • Tools
    • Network
      • What's my IP
      • WHOIS IP
      • Domain WHOIS
      • Geolocate IP
      • DNS Lookup
      • DNS Propagation
      • ASN Lookup
      • Reverse Lookup
      • Domain monitoring
    • Image Compressor
    • MCP Servers
  • Products
    • Whatsboost
      • Whatsboost PrestaShop
      • Whatsboost WordPress
      • Whatsboost Shopify
    • Ulix
      • Extension QR para navegador
    • Chatbot
      • Chatbot WhatsApp
      • Chatbot Instagram
      • Chatbot Facebook
      • Chatbot TikTok
    • VeriFactu
    • Web TV
      • Mis pantallas
      • Vincular nueva TV
      • Dispositivos vinculados
      • Releases APK
      • Pantallas por cliente
    • Control de Fichajes

5 News at ALMC
  • Inauguration of the... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    Inauguration of the...It was a very busy and special day. 30 Jun 2025
  • Website Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    WebsiteI recover the domain I had in the past and set up... 01 Jun 2025
  • Signing of the Lease... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    Signing of the Lease...After spending some time looking for premises, my... 01 Jun 2025
  • ALMC returns and com... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    ALMC returns and com...We reactivate the brand with ALMC SECURITY SL (CIF... 23 Apr 2025
  • feb. 2025 Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    feb. 2025The decision to start entrepreneurship again was b... 01 Feb 2025

View all news

NPM Supply Chain Attack: How a Malicious SDK Compromised Crypto Wallets

  1. Home
  2. Blog
  3. Categories
  4. Cybersecurity
  5. NPM Supply Chain Attack: How a Malicious SDK...
  • All articles
  • Categories
  • Tags
  • Statuses

NPM Supply Chain Attack: How a Malicious SDK Compromised Crypto Wallets

A Wake-Up Call for Development TeamsIn a recent incident that sent ripples through the JavaScript ecosystem, a popular SDK for the Injective blockchai...

A Wake-Up Call for Development Teams

In a recent incident that sent ripples through the JavaScript ecosystem, a popular SDK for the Injective blockchain was compromised on the npm registry. The malicious version, @injectivelabs/sdk-ts 1.20.21, was designed to steal cryptocurrency wallet credentials from developers who used it. This attack highlights a growing threat: supply chain vulnerabilities that can turn trusted tools into silent data thieves.

Robotic arm unlocking a padlock over a stream of code representing a supply chain attack

For system administrators and hosting companies, this is more than a news story. It's a reminder that the software we rely on daily can become a vector for attacks, and that proactive security measures are no longer optional.

How the Attack Unfolded

The attackers gained control of a legitimate contributor's GitHub account, allowing them to inject malicious code into the SDK. They then published the compromised version to npm, along with 17 other packages linked to the project. By pinning these packages to the infected dependency, they maximized the impact across projects that install the entire suite.

The malware was particularly insidious: it didn't execute during installation. Instead, it activated when developers used functions to create or import wallets. At that moment, the code captured the mnemonic phrase and private key, encoded them in base64, and sent them via an HTTP POST request to an endpoint that appeared to be part of Injective's public infrastructure. This clever camouflage made the exfiltration look like normal telemetry traffic.

Why This Matters for Your Servers

While this specific attack targeted cryptocurrency wallets, the underlying technique is universal. Malicious packages can be designed to steal any kind of sensitive data, from API keys to database credentials. For businesses in Spain, where GDPR compliance is critical, a breach of this nature can have legal and financial repercussions.

The incident also underscores the importance of monitoring outbound traffic. The malware grouped multiple keys and sent them in the request header, which resulted in abnormally large headers—a telltale sign that could be caught by vigilant network monitoring.

Immediate Steps to Mitigate Risk

If your team has used the affected SDK, the first step is to treat any wallet credentials as compromised. Move funds to new wallets immediately and consider the old ones burned. Rotate any secrets that may have been exposed on the same machines, including tokens, API keys, and deployment credentials.

Next, audit your repositories, lockfiles, and CI/CD logs to determine if the malicious version was ever installed. Even if you've updated to a clean version, the damage may already be done. Review outbound traffic for unusual POST requests that match the pattern described.

Strengthening Your Supply Chain Defenses

This attack is a classic example of a supply chain compromise. To defend against such threats, adopt a multi-layered approach:

  • Pin versions rigorously and avoid floating dependencies that can silently pull in malicious updates.
  • Implement integrity checks in your build pipeline to verify that packages haven't been tampered with.
  • Conduct regular dependency audits to identify known vulnerabilities.
  • Enforce MFA on all accounts that have publishing rights to your code repositories.
  • Isolate build environments and limit access to secrets in CI/CD using the principle of least privilege.

How Abuse Shield Can Help

At ALMC.es, we understand that managing server security across multiple machines is a daunting task. That's why we developed Abuse Shield, a solution that centralizes your server protection. It automatically blocks malicious IPs, manages fail2ban across your entire infrastructure, and shares a reputation feed among all your servers. This means that if one server detects a threat, all others are immediately protected.

By integrating Abuse Shield into your security strategy, you can focus on development while we handle the constant monitoring and response. Our service is designed for system administrators, hosting companies, and SMEs with their own servers, providing peace of mind in an increasingly hostile digital landscape.

Conclusion

The npm attack serves as a stark reminder that no software is inherently safe. By staying informed, implementing robust security practices, and leveraging specialized tools like Abuse Shield, you can significantly reduce your risk. Don't wait for an incident to occur—take proactive steps today to secure your servers and protect your business.

Related

  • Hugging Face Breach: Why Data Pipelines Are the New Security Frontier
  • FakeGit: How Fake GitHub Repos Spread SmartLoader and StealC
  • Critical WordPress Flaw 'wp2shell' Exploited: Act Now to Secure Your Servers
  • Desarrollo web

Put these ideas into practice

Talk to ALMC about a solution for your business. Explore your options or contact our team.

Soluciones ALMC

Server Management & Monitoring
Process Automation Scripts and Bots
Monitoring & Incident Response (SIEM)
Cloud Security (AWS, Azure, Google Cloud)
Process Automation (Scripts and Bots)
Relacionados
  • SonicWall SMA1000 Zero-Days: Urgent Patch Guidance for SysAdmins
    Cybersecurity · 54 minutes ago
  • UEFI Secure Boot Bypass: Why Old Shims Threaten Your Servers
    Cybersecurity · 54 minutes ago
  • Evilginx and Device Code Phishing: Lessons from a Misconfigured Server
    Cybersecurity · 54 minutes ago
  • RoguePlanet: Microsoft Patches Defender Zero-Day, Update Now
    Cybersecurity · 54 minutes ago
  • GhostLock CVE-2026-43499: Patch Your Linux Servers Now
    Cybersecurity · 54 minutes ago
  • Fastjson 1.x RCE: A Practical Guide for System Administrators
    Cybersecurity · 1 hour ago
Servidores MCP Destacados
  • Paddle Billing
    Cloud Service
  • Gaggiuino MCP
    Other
  • Whoop
    Productivity
  • MCP Oracle Database Server
    Database
  • CData Reckon
    Database
  • API Docs MCP
    Communication
  • Image Tools MCP
    Development
  • Thirdweb
    Official 🌟 Oficial
  • Obenan Review Analyzer
    Other
Ver todos los servidores MCP
Cybersecurity · Blog Brain · 2026-09-08
Cerrar panel
Your ecosystem

SaaS applications

Open each workspace directly with your ALMC account.

My account Create account
VeriFactuVerified invoicingAbuse ShieldWeb securityWhatsBoostSales and CRMCommerceStore and POSEmail AISmart emailWebTVDigital signageTime trackingWorking-time controlPrintFlowPrint workflows
Agente Smith · ALMCAgente IA propio on-premise

Hola 👋 Soy Smith, el agente IA de ALMC. Pregúntame sobre ciberseguridad, IA, desarrollo a medida o nuestros productos SaaS.

¿Prefieres hablar con persona? Contacto humano

ALMC access centre

One account · All your services

Start wherever you want.

Create an account to centralise your services, or ask for guidance if you do not know what you need yet.

Create account Talk to ALMC

Explore by product

VeriFactuInvoicingAbuse ShieldSecurityWhatsBoostSalesCommerceStore and POSEmail AIAutomationWebTVDigital signage

Sign in to your account.

The same sign-in brings together your services, team and billing.

Enter my panelAccess your services, team and billing.
Sign in

Not a client yet? Create an account

ALMC Security Logo

Experts in cybersecurity, custom Laravel development, and server management. We deliver robust, secure, and personalized technological solutions.

Latest News

Inauguration of the first office in Lleida of ALMC SECURITY SL
Inauguration of the first office in Lleida of ALMC...
30 Jun 2025
Website
01 Jun 2025
Signing of the Lease Contract
Signing of the Lease Contract
01 Jun 2025

Main Services

  • desarrollo web lleida
  • tienda online a medida
  • chatbot ia empresa
  • automatización procesos empresa
  • desarrollo aplicaciones móviles

Suite SaaS

  • PrintFlow (copisterías)
  • WebTV (cartelería)
  • VeriFactu (facturación)
  • Fichaje horario

Contact

  • Rambla de Ferran, 37, 25007 Lleida

  • +34 614 443 757

  • info@almc.es

Follow Us

Useful links

  • About us
  • Contact
  • Reserva cita
  • Hacked website repair
  • Website maintenance
  • Website repair
  • Tools
  • What is my IP
  • Compress images
  • Site search
  • Blog

© Copyright 2026. ALMC SECURITY S.L.U.

  • Legal
      • Privacy Policy
      • Terms and Conditions of Service
      • Legal Notice and Corporate Information
      • Cookie Policy
  • Resources
    • Blog
    • Sitemap

ALMC

Legal

This site only uses first-party cookies and local browser storage, and only to make it work: keeping your session, protecting forms, remembering your language and not showing you this notice again. We use no analytics or advertising cookies, there are no third-party cookies and we do not build profiles. As strictly necessary technical cookies, they are exempt from consent under Article 22.2 of the Spanish LSSI-CE: this notice is informative and the button only stops it from appearing again. You can delete or block them from your browser, though some features may then stop working. Cookie Policy · Privacy Policy.

Chat now
Call Sales
+34 614 443 757

More ways to contact us

¿Hablamos directamente?

Reserva una cita en mi agenda — yo te llamo o nos vemos por Google Meet

  • ✓Confirmación instantánea por WhatsApp
  • ✓Disponibilidad en tiempo real
  • ✓Recordatorio 1h antes
  • ✓Cancela o cambia hora con un click
Initial consultation · 30min
📅 Ver disponibilidad y reservar